57,566 vulnerabilities published in 2026
In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_pipapo_avx2: don't return non-ma
In the Linux kernel, the following vulnerability has been resolved: net/tcp-md5: Fix MAC comparison to be constant-time
phpVMS is a PHP application to run and simulate an airline. Prior to version 7.0.6, a critical vulnerability in phpVMS a
Grav is a file-based Web platform. Prior to 2.0.0-beta.2, the Login::register() method in the Login plugin accepts attac
oxyno-zeta/s3-proxy is an aws s3 proxy written in go. Prior to 5.0.0, s3-proxy contains an authentication bypass caused
Scramble generates API documentation for Laravel project. From 0.13.2 to before 0.13.22, when documentation endpoints ar
Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.31.0, the default deny-lists used by Gotenberg's d
Gradient is a nix-based continuous integration system. In 1.1.0, when GRADIENT_DISCOVERABLE=true (the default, and the N
Dify version 1.14.1 and prior contain a path traversal vulnerability that allows authenticated users to manipulate reque
free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF mounts the 3gpp-pfd-manag
free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF mounts the 3gpp-traffic-i
High-risk TrustAllCerts routines disable standard TLS certificate validation. Combined with hard-coded DES symmetric enc
AdGuard Home, when started with the --glinet flag, contains an authentication bypass vulnerability that allows unauthent
Hermes WebUI before version 0.51.358 contains an improper access control vulnerability that allows unauthenticated remot
Cap-go before 12.128.2 contains an authentication bypass vulnerability in OTP verification that allows attackers to bypa
In the Linux kernel, the following vulnerability has been resolved: netfilter: require Ethernet MAC header before using
WebSocket endpoints lack proper authentication mechanisms, enabling attackers to impersonate charging stations. As a res
Budibase is an open-source low-code platform. Prior to 3.39.0, an anonymous attacker who knows or can enumerate a worksp
fast-mcp-telegram is a Telegram MCP Server. Prior to 0.19.1, fast-mcp-telegram validates HTTP Bearer tokens by joining t
Authorization bypass through User-Controlled key vulnerability in Vimesoft Inc. Enterprise Video Platform allows Accessi
In the Linux kernel, the following vulnerability has been resolved: net: skmsg: preserve sg.copy across SG transforms
In the Linux kernel, the following vulnerability has been resolved: tcp: fix stale per-CPU tcp_tw_isn leak enabling ISN
A flaw was found in the Konnectivity proxy-server configuration for hosted control planes. The agent-facing listener was
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.224, the public
Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Install). The
Vulnerability in the PeopleSoft Enterprise FIN Expenses product of Oracle PeopleSoft (component: Expenses). The suppor
An attacker may perform unauthenticated read and write operations on sensitive filesystem areas via the AppEngine Fileac
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 t
The CHARX JupiCore service allows an unauthenticated remote attacker to reconfigure charging points. This can lead to di
CodeIgniter is a PHP full-stack web framework. From 4.3.0 through 4.7.3, Query Builder deleteBatch() substitutes bound v
The Simple Membership WordPress plugin before 4.7.8 does not verify whether user creation failed during registration bef
The Conditional Authentication (Adaptive Authentication) script does not correctly enforce the completion of all require
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to ver
Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to el
An unauthenticated command injection vulnerability was identified in the GMS Dispatcher Service in GMS 9.5.1 and earlier
Yuxi is a large-model-based intelligent knowledge base and knowledge graph agent development platform. Prior to version
Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.8, create_mobi
Vitest is a testing framework powered by Vite. Prior to versions 3.2.7, 4.1.10, and 5.0.0-beta.6, Browser Mode provider
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 IBM WebSphere Application Server Liberty is vulnera
In the Linux kernel, the following vulnerability has been resolved: cifs: validate DFS referral string offsets parse_d
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.
Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authenticatio
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to obtain sensitive information due to an in
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who has an embedded repo
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who has an embedded repo
In Splunk Enterprise versions below 10.4.1, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who can read the Hyperte
exceljs through 4.4.0 contains a prototype pollution vulnerability in the deepMerge helper that fails to reject __proto_
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started